CVE-2026-8835Disclosure(ibm / aix)

LOWCVSS 7.3 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch ibm aix systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

IBM HTTP Server 8.5, and 9.0 is vulnerable to invalid pointer dereference. A privileged user, authenticated to the Administration Server, could exploit this vulnerability to expose sensitive information or cause a denial of service.

1.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-822

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • aix
  • http_server
  • linux_kernel
  • windows

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 1 mentions (2026-05-26); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Products
aixhttp_serverlinux_kernelwindowsz\/os

1 version affected across 5 products

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-05-26: 1Mentions · 2026-05-27: 1Mentions · 2026-05-28: 1Patch / Workaround · 2026-05-28: 1Technical Details · 2026-05-26: 1Technical Details · 2026-05-27: 1Technical Details · 2026-05-28: 105-2605-2705-28
Signal classification1 categories
Disclosure
3100.0%
Referenced assets2 URLs
Full discourse3 posts
  • DFIR Lab@DFIR_Lab
    Disclosure

    🚨 HIGH: CVE-2026-8835 (CVSS 7.3) IBM HTTP Server 8.5 & 9.0 vulnerable to invalid pointer dereference. Privileged users can expose sensitive data or cause DoS via Admin Server. Patch immediately. #CVE #PatchNow #ThreatIntel https://t.co/WyYW2qOf6F

    Post summary

    IBM HTTP Server 8.5 and 9.0 have a high‑severity CVE‑2026‑8835 that allows privileged users to cause DoS or exfiltrate data via the Admin Server; users are urged to patch immediately.

    0000045
    30 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🟠 #IBM HTTP Server, Invalid Pointer Dereference, #CVE-2026-8835 (Medium) https://dailycve.com/ibm-http-server-invalid-pointer-dereference-cve-2026-8835-medium/

    Post summary

    The post announces CVE‑2026‑8835, an invalid pointer dereference issue in IBM HTTP Server with Medium severity; no proof‑of‑concept, exploitation details, or patch information are included.

    0000052
    207 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-8835 IBM HTTP Server 8.5, and 9.0 is vulnerable to invalid pointer dereference. A privileged user, authenticated to the Administration Server, could exploit this vulnerabili… https://www.cve.org/CVERecord?id=CVE-2026-8835

    Post summary

    The paragraph reports on IBM HTTP Server CVE-2026-8835, identifying its invalid pointer dereference flaw and privileged user context, but provides no PoC, exploit, patch, or evidence of active use.

    00000186
    57.5K followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
OSibmaix---
Appibmhttp_server---
OSibmz\/os---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more